Junglewise Threat Intelligence

CVE-2026-54886: Erlang OTP infinite loop in ssh_sftpd module

CVE-2026-54886 · Severity: info · CVSS 5.3 · Published 2026-07-02

Technologies: Erlang OTP. Vendors: Erlang.

Executive brief

A vulnerability in the Erlang OTP SSH library allows an authenticated user to crash or freeze SFTP file transfer channels. By sending specially crafted data packets, an attacker can force the server into an infinite loop, consuming excessive CPU and memory. This can lead to a denial of service where the file transfer service becomes unresponsive to legitimate users.

Technical details

A 'Loop with Unreachable Exit Condition' (CWE-835) exists in the ssh_sftpd:handle_data/4 function within lib/ssh/src/ssh_sftpd.erl. The function contains a catch-all clause that accepts SSH_MSG_CHANNEL_EXTENDED_DATA (non-zero type codes). When such data arrives with an empty pending buffer and a payload within the SFTP packet size limit, the function performs a tail-call to itself with identical arguments, resulting in an infinite loop. While the BEAM scheduler prevents total node starvation, the affected process consumes 100% of its CPU share and its message queue grows boundlessly. Attackers can amplify this by opening multiple channels if max_channels is set to infinity. Patches are available in OTP versions 29.0.3, 28.5.0.3, and 27.3.4.14.

Affected products

  • Erlang OTP 17.0 to 27.3.4.13, 28.0 to 28.5.0.2, 29.0 to 29.0.2
  • Erlang ssh (OTP) 3.0.1 to 5.2.11.8, 5.3.0 to 5.5.2.1, 6.0.0 to 6.0.1

Timeline

  • 2026-07-02: advisory
  • 2026-07-02: patched

References